feat: initial ArgoCD GitOps self-management setup
Validate manifests / validate (push) Failing after 4s

- Base references upstream ArgoCD v3.3.6 install.yaml
- Production overlay applies all cluster customizations:
  - KSOPS CMP sidecar on argocd-repo-server
  - Custom ConfigMaps (argocd-cm, argocd-cmd-params-cm, argocd-rbac-cm, argocd-notifications-cm)
  - Redis migrated to shared-redis.data:6379
  - Traefik IngressRoute for argocd.olb42.com
  - SOPS-encrypted secrets (age key, redis auth, gitea tokens, repo-creds)
- Bootstrap Application with prune:false for safe self-management
This commit is contained in:
2026-04-19 23:36:09 +01:00
commit 40eb3b842c
17 changed files with 531 additions and 0 deletions
+29
View File
@@ -0,0 +1,29 @@
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: argocd-production
namespace: argocd
labels:
app.kubernetes.io/managed-by: argocd
app.kubernetes.io/name: argocd
spec:
project: default
source:
repoURL: http://gitea-ha-http.apps:3000/olb42/argocd.git
targetRevision: main
path: manifest/overlays/production
plugin:
name: ksops
destination:
server: https://kubernetes.default.svc
namespace: argocd
syncPolicy:
automated:
# prune: false — ArgoCD self-managing itself; never auto-prune to avoid
# accidentally removing ArgoCD components and losing cluster management.
prune: false
selfHeal: true
syncOptions:
- CreateNamespace=false
- ApplyOutOfSyncOnly=true
- ServerSideApply=true
+3
View File
@@ -0,0 +1,3 @@
enabled: true
target_namespace: argocd
apply_from_branch: main